URLhaus Database

You are currently viewing the URLhaus database entry for http://87.249.142.126:60800/AV.scr which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3655825
URL: http://87.249.142.126:60800/AV.scr
URL Status:Offline
Host: 87.249.142.126
Date added:2025-10-04 05:09:32 UTC
Last online:2026-06-09 02:XX:XX UTC
Threat:Malware download Malware download
Reporter: Riordz
Abuse complaint sent (?): Yes (2025-10-04 05:10:28 UTC to abuse-ttnet{at}ttnet[dot]cz)
Takedown time:8 months, 7 days, 21 hours, 45 minutes Bad (down since 2026-06-09 02:55:51 UTC)
Tags:CoinMiner

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2026-05-08AV.screxe 007b0513a828eadee25ad16bf6e8eeacafe621e0adf4f6c6d03bd35bc4047e31n/a 
2026-05-08AV.screxe a23b9f2254554d694fd9538cfc85dd72b6d9dc8084c3a48fdbafaa043aa87f7bn/a 
2026-04-25AV.screxe 163ade9d672ac8f4b1dabb7bbf173c8191ec47a7bab75bef9664020c028d708fn/a CoinMiner
2026-01-12AV.screxe 12953b8ef0d027787ac6dbe477ea58ab3535d3e85558a10b9936bf3914973874n/a 
2026-01-10AV.screxe 20d0cc1cf16ed908eaeb5bf617b213d28619bb1810577804ec30ebf402c47ec4n/a 
2026-01-08AV.screxe 778efe083950ba83267aa098522c0a3040dedd9eebca437470850ff0ad3e6444n/a 
2026-01-05AV.screxe 014cd33e08e15c6fcfb383e59764c9b054ebd149487c10397784acc8dd2a24f8n/a 
2026-01-03AV.screxe fd998620bc343d829d711d5b62896bec1f365d7bf7a6b6de92a5e61959477113n/a 
2025-10-04AV.screxe 5d9fe2735d4399d98e6e6a792b1feb26d6f2d9a5d77944ecacb4b4837e5e5fcaVirustotal results 81.69%CoinMiner